> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://api.docs.modulards.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://api.docs.modulards.com/_mcp/server.

# Update a website's Malware Scanner settings

PATCH https://api.modulards.com/api/public/v1/malware-scan-services/{site_preset_malware_scan}
Content-Type: application/json

Changes how one website is scanned. Send only the fields you want to change, and at least one.

The schedule and `content.excluded` are not edited here: the schedule comes from the global configuration and exclusions are a dashboard-only setting. Changing `filesystem` always resets the exclusions to the new mode's default, and resets the scanned areas too unless you send `content.included` in the same request.

**Body**
- `status` (`enabled` or `disabled`, optional): turns scanning on or off.
- `preset` (integer, optional): id of another Malware Scanner global configuration to move the website to (ids come from "List Malware Scanner global configurations"). The website keeps its status. Moving a website to a premium configuration adds it to the premium tier, which is metered per website and per month, with no websites included in the plan. To assign many websites to one configuration at once, always switching them on, use "Assign websites to a Malware Scanner global configuration" instead.
- `filesystem` (string, optional): which areas are scanned. It is valid on its own.
- `content.included` (array of strings, optional): the areas to scan; it requires `filesystem` in the same request.

**Errors**
- **404**: `preset` belongs to another organization.
- **409**: `status` is `enabled` on a website that is paused and not yet registered with the scanning provider. A website the assignment already switched on keeps accepting `status: enabled` while its registration runs.
- **409**: `preset` is a premium configuration and the organization has not subscribed the premium Malware Scanner add-on. The user subscribes it from the Modular DS dashboard and the same request then goes through; an integration never buys it. The message reads "The premium Malware Scanner add-on must be active to use a premium global configuration."
- **422**: no field is sent (the message is "Send at least one field to update: status, preset, filesystem or content."), `content.excluded` or `schedule` is sent, or `preset` is not a Malware Scanner configuration.

Reference: https://api.docs.modulards.com/modular-ds-public-api/malware-scanner/malware-scanner-settings/update-a-website-s-malware-scanner-settings

## Authentication

- `Authorization` header (bearer token, required) — Personal access token created in the Modular DS dashboard; read-only tokens can only call GET endpoints.

## Request

### Path parameters

- `site_preset_malware_scan` (string, required)

### Query parameters

- `include` (string, optional) — Relations to add to the answer: `preset` (the global configuration the website uses). Without `include` it is answered; an empty `include=` answers none. Any other name answers 400.

### Body (application/json)

This endpoint expects an object.

- `status` (string, optional)

## Response

### 200

200 - Malware scan service updated

- `data` (ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaData, optional)
- `jsonapi` (ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaJsonapi, optional)

## Errors

### 409 Conflict Error

409 - Website paused and not yet registered with the scanning provider

- `errors` (list of ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaErrorsItems, optional)
- `jsonapi` (ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaJsonapi, optional)

## Types

### ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaData

- `attributes` (ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataAttributes, optional)
- `id` (string, optional)
- `links` (ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataLinks, optional)
- `relationships` (ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataRelationships, optional)
- `type` (string, optional)

### ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaJsonapi

- `version` (string, optional)

### ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaErrorsItems

- `detail` (string, optional)
- `status` (string, optional)
- `title` (string, optional)

### ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataAttributes

- `content` (ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataAttributesContent, optional)
- `created_at` (string, optional)
- `filesystem` (string, optional)
- `last_request` (string, optional)
- `limits` (ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataAttributesLimits, optional, nullable) — Scan quota of the website; null until its first scan runs.
- `next_request` (string, optional)
- `preset_type` (string, optional) — Kind of global configuration the website follows, for example malware_scan_basic.
- `schedule` (ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataAttributesSchedule, optional)
- `status` (string, optional)
- `tier` (enum, optional) — Scanner tier the website uses, inherited from its global configuration.
  - Allowed values: `basic`, `premium`
- `updated_at` (string, optional)

### ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataLinks

- `self` (string, optional)

### ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataRelationships

- `preset` (ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataRelationshipsPreset, optional)

### ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataAttributesContent

- `excluded` (ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataAttributesContentExcluded, optional)
- `included` (list of string, optional)

### ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataAttributesLimits

Scan quota of the website; null until its first scan runs.

- `cleans_limit` (integer, optional) — File cleanups allowed per monthly window.
- `cleans_used` (integer, optional) — File cleanups used in the current monthly window.
- `db_cleans_limit` (integer, optional) — Database cleanups allowed per monthly window.
- `db_cleans_used` (integer, optional) — Database cleanups used in the current monthly window.
- `db_resets_at` (datetime, optional, nullable) — When the database window ends; null until it is known.
- `db_scans_limit` (integer, optional) — Database scans allowed per monthly window.
- `db_scans_used` (integer, optional) — Database scans used in the current monthly window.
- `resets_at` (datetime, optional, nullable) — When the file scan window ends and its counters reset; null until the first scan.
- `scans_limit` (integer, optional) — File scans allowed per monthly window.
- `scans_used` (integer, optional) — File scans used in the current monthly window.

### ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataAttributesSchedule

- `day_month` (double, optional)
- `day_week` (any, optional, nullable)
- `frequency` (string, optional)
- `start_hour` (string, optional)
- `timezone` (string, optional)

### ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataRelationshipsPreset

- `data` (ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataRelationshipsPresetData, optional)

### ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataAttributesContentExcluded

- `content` (any, optional, nullable)
- `core` (any, optional, nullable)
- `database` (any, optional, nullable)
- `fonts` (any, optional, nullable)
- `mu_plugins` (any, optional, nullable)
- `plugins` (any, optional, nullable)
- `themes` (any, optional, nullable)
- `uploads` (any, optional, nullable)

### ApiPublicV1MalwareScanServicesSitePresetMalwareScanPatchResponsesContentApplicationJsonSchemaDataRelationshipsPresetData

- `id` (string, optional)
- `type` (string, optional)

## Examples

### 200 - Malware scan service updated

**Response**

```json
{
  "data": {
    "attributes": {
      "content": {
        "excluded": {
          "content": null,
          "core": null,
          "database": null,
          "fonts": null,
          "mu_plugins": null,
          "plugins": null,
          "themes": null,
          "uploads": null
        },
        "included": [
          "core",
          "database"
        ]
      },
      "created_at": "2026-07-01T09:00:00.000000Z",
      "filesystem": "default",
      "last_request": "2026-09-01T03:00:00.000000Z",
      "limits": {
        "cleans_limit": 0,
        "cleans_used": 0,
        "db_cleans_limit": 0,
        "db_cleans_used": 0,
        "db_resets_at": "2026-10-01T00:00:00.000000Z",
        "db_scans_limit": 30,
        "db_scans_used": 1,
        "resets_at": "2026-10-01T00:00:00.000000Z",
        "scans_limit": 30,
        "scans_used": 1
      },
      "next_request": "2026-10-01T03:14:00.000000Z",
      "preset_type": "malware_scan_basic",
      "schedule": {
        "day_month": 1,
        "day_week": null,
        "frequency": "monthly",
        "start_hour": "03:00",
        "timezone": "Europe/Madrid"
      },
      "status": "enabled",
      "tier": "basic",
      "updated_at": "2026-09-18T10:30:00.000000Z"
    },
    "id": "845",
    "links": {
      "self": "https://api.modulards.com/api/public/v1/malware-scan-services/845"
    },
    "relationships": {
      "preset": {
        "data": {
          "id": "7",
          "type": "preset-malware-scans"
        }
      }
    },
    "type": "site-preset-malware-scans"
  },
  "jsonapi": {
    "version": "1.1"
  }
}
```

**SDK Code**

```python 200 - Malware scan service updated
import requests

url = "https://api.modulards.com/api/public/v1/malware-scan-services/site_preset_malware_scan"

headers = {"Authorization": "Bearer <token>"}

response = requests.patch(url, headers=headers)

print(response.json())
```

```javascript 200 - Malware scan service updated
const url = 'https://api.modulards.com/api/public/v1/malware-scan-services/site_preset_malware_scan';
const options = {method: 'PATCH', headers: {Authorization: 'Bearer <token>'}};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go 200 - Malware scan service updated
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.modulards.com/api/public/v1/malware-scan-services/site_preset_malware_scan"

	req, _ := http.NewRequest("PATCH", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby 200 - Malware scan service updated
require 'uri'
require 'net/http'

url = URI("https://api.modulards.com/api/public/v1/malware-scan-services/site_preset_malware_scan")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

```java 200 - Malware scan service updated
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.patch("https://api.modulards.com/api/public/v1/malware-scan-services/site_preset_malware_scan")
  .header("Authorization", "Bearer <token>")
  .asString();
```

```php 200 - Malware scan service updated
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.modulards.com/api/public/v1/malware-scan-services/site_preset_malware_scan', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
  ],
]);

echo $response->getBody();
```

```csharp 200 - Malware scan service updated
using RestSharp;

var client = new RestClient("https://api.modulards.com/api/public/v1/malware-scan-services/site_preset_malware_scan");
var request = new RestRequest(Method.PATCH);
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

```swift 200 - Malware scan service updated
import Foundation

let headers = ["Authorization": "Bearer <token>"]

let request = NSMutableURLRequest(url: NSURL(string: "https://api.modulards.com/api/public/v1/malware-scan-services/site_preset_malware_scan")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "PATCH"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### Update a website's Malware Scanner settings

**Request**

```json
{
  "status": "enabled"
}
```

**Response**

```json
{
  "data": {
    "attributes": {
      "content": {
        "excluded": {
          "content": null,
          "core": null,
          "database": null,
          "fonts": null,
          "mu_plugins": null,
          "plugins": null,
          "themes": null,
          "uploads": null
        },
        "included": [
          "core",
          "database"
        ]
      },
      "created_at": "2026-07-01T09:00:00.000000Z",
      "filesystem": "default",
      "last_request": "2026-09-01T03:00:00.000000Z",
      "limits": {
        "cleans_limit": 0,
        "cleans_used": 0,
        "db_cleans_limit": 0,
        "db_cleans_used": 0,
        "db_resets_at": "2026-10-01T00:00:00.000000Z",
        "db_scans_limit": 30,
        "db_scans_used": 1,
        "resets_at": "2026-10-01T00:00:00.000000Z",
        "scans_limit": 30,
        "scans_used": 1
      },
      "next_request": "2026-10-01T03:14:00.000000Z",
      "preset_type": "malware_scan_basic",
      "schedule": {
        "day_month": 1,
        "day_week": null,
        "frequency": "monthly",
        "start_hour": "03:00",
        "timezone": "Europe/Madrid"
      },
      "status": "enabled",
      "tier": "basic",
      "updated_at": "2026-09-18T10:30:00.000000Z"
    },
    "id": "845",
    "links": {
      "self": "https://api.modulards.com/api/public/v1/malware-scan-services/845"
    },
    "relationships": {
      "preset": {
        "data": {
          "id": "7",
          "type": "preset-malware-scans"
        }
      }
    },
    "type": "site-preset-malware-scans"
  },
  "jsonapi": {
    "version": "1.1"
  }
}
```

**SDK Code**

```python Update a website's Malware Scanner settings
import requests

url = "https://api.modulards.com/api/public/v1/malware-scan-services/site_preset_malware_scan"

payload = { "status": "enabled" }
headers = {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.patch(url, json=payload, headers=headers)

print(response.json())
```

```javascript Update a website's Malware Scanner settings
const url = 'https://api.modulards.com/api/public/v1/malware-scan-services/site_preset_malware_scan';
const options = {
  method: 'PATCH',
  headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
  body: '{"status":"enabled"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go Update a website's Malware Scanner settings
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.modulards.com/api/public/v1/malware-scan-services/site_preset_malware_scan"

	payload := strings.NewReader("{\n  \"status\": \"enabled\"\n}")

	req, _ := http.NewRequest("PATCH", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby Update a website's Malware Scanner settings
require 'uri'
require 'net/http'

url = URI("https://api.modulards.com/api/public/v1/malware-scan-services/site_preset_malware_scan")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"status\": \"enabled\"\n}"

response = http.request(request)
puts response.read_body
```

```java Update a website's Malware Scanner settings
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.patch("https://api.modulards.com/api/public/v1/malware-scan-services/site_preset_malware_scan")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"status\": \"enabled\"\n}")
  .asString();
```

```php Update a website's Malware Scanner settings
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.modulards.com/api/public/v1/malware-scan-services/site_preset_malware_scan', [
  'body' => '{
  "status": "enabled"
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp Update a website's Malware Scanner settings
using RestSharp;

var client = new RestClient("https://api.modulards.com/api/public/v1/malware-scan-services/site_preset_malware_scan");
var request = new RestRequest(Method.PATCH);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"status\": \"enabled\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift Update a website's Malware Scanner settings
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = ["status": "enabled"] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.modulards.com/api/public/v1/malware-scan-services/site_preset_malware_scan")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "PATCH"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```